On 5 Apr 2000, Ash R. J. Wyllie wrote:
> That's a good question. For Be I have to have 48000 to 65535 open. On the
> other hand, as I understand it, If there is no program on the lan port side of
> the firewall to do something with the incoming packet, nothing will happen to
> any of the machines on the lan.
Correct.
> In this instance I suppose some one could trap the dns lookup packet and then
> send back a fake IP address. That would then send the requesting program off
> to the site chosen by the attacker. Which might be a problem.
True, and there's nothing a firewall can do about it. There are schemes
involving cryptographic authentication for DNS, but they're not widely
used yet. In general, you theoretically can't trust *anything* in the
outside world without crypto.
> Holger, I presume the tcp auto setting allows only known (telnet or ftp say)
> ports open to the internet?
By default, no "service" ports are allowed at all, and you need explicit
entries to permit them. That's why an entry for ident is explicitly
included by default.
Fred Wright
--
To unsubscribe send "unsubscribe miami-talk-ml" to
"[EMAIL PROTECTED]". For help on list commands send "help" to
"[EMAIL PROTECTED]".